Real-time Security Situational Model for System State Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security tools can only operate retrospectively to detect security exploits due to the high computational cost of building comprehensive logs of system activities, placing them at a disadvantage against attackers.

Innovation Solution

A situational model representing the security-relevant state of monitored devices is constructed in real-time, allowing for the validation of state information and serving as a cache for computationally expensive or high-latency information, enabling real-time detection and response to security threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive logs of system activities are built for security analysis, then security exploit detection capability is improved, but computational cost and processing time increase significantly

Engineering Contradiction:
Improvesecurity exploit detection capabilityVSAvoidcomputational cost
Core Design Contradiction:
ReliabilityVSUse of energy by stationary object

Solution Approach 1:

The patent extracts only the essential security-relevant state information from comprehensive system logs, building a situational model that contains only critical security data rather than processing complete system activity logs. This extraction approach maintains security detection capability while dramatically reducing computational overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the security monitoring system into two parts: a lightweight situational model that tracks essential security state, and optional comprehensive logging for detailed analysis. This segmentation allows the system to maintain continuous security awareness with minimal computational cost while preserving the ability to perform deep analysis when needed.

Inventive Principle:
Principle #1Segmentation

2Reliability

If comprehensive logs of system activities are built for security analysis, then security exploit detection capability is improved, but real-time detection capability deteriorates

Engineering Contradiction:
Improvesecurity exploit detection capabilityVSAvoidreal-time detection capability
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent performs preliminary action by continuously maintaining a situational model that pre-processes and structures security-relevant state information as events occur. This preliminary structuring eliminates the need for computationally intensive log processing during detection, enabling real-time security analysis while preserving comprehensive detection capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a simplified copy of system state information in the situational model that contains only security-relevant data. This copy allows for rapid querying and analysis without requiring access to or processing of the complete system logs, thereby enabling real-time detection while maintaining thorough security monitoring.

Inventive Principle:
Principle #26Copying

3Loss of information

If events are written multiple times to logs with cross input/output boundaries, then completeness of security data is improved, but processing efficiency decreases

Engineering Contradiction:
Improvecompleteness of security dataVSAvoidprocessing efficiency
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The patent introduces an intermediary situational model that receives and structures security-relevant information from system events. This intermediary layer processes events once and maintains a structured representation, eliminating the need for multiple log writes and cross-boundary processing while preserving complete security data for analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10409980B2Real-time representation of security-relevant system state
Publication Date: 2019.09.10 CROWDSTRIKE
  • US10409980B2 patent drawing
  • US10409980B2 patent drawing
  • US10409980B2 patent drawing

AI summary

A situational model representing of a state of a monitored device is described herein. The situational model is constructed with the security-relevant information in substantially real-time as execution activities of the monitored device associated with the security-relevant information are observed. The represented state may include a current state and a past state of the monitored device. Also, the situational model may be used to validate state information associated events occurring on the monitored device. Further, a remote security service may configure the monitored device, including configuring the situational model, and may build an additional situational model representing a state of a group of monitored devices.